REIZAN · AI-NATIVE CYBER ADVISORY · LATAM CRITICAL INFRASTRUCTURE

The coverage your
audit cannot reach.

Only 1.7% of Chile’s 915 critical-infrastructure operators publish a verifiable vulnerability-disclosure channel. We cover the ground that Big Four audits and pentests structurally miss — aligned with ISO/IEC 29147.

FrameworkLaw 21.663 · ANCI
OIV universe915 OIVs · 1.7% with channel
MethodologyCoverage Gap Closure
Public paperPublished · Zenodo · DOI
§ 02 · Capabilities

What an AI-native advisory delivers.

Three capabilities integrated into a single practice.

C.01 /

Continuous research

Continuous research that measures the exposure of regulated critical infrastructure across LATAM at scale. AI-native advisory means senior advisor judgment is encoded into the practice, not bottlenecked behind one founder’s calendar.

  • Coverage Gap Method™
  • Public paper · Zenodo · DOI
  • Apache 2.0 tooling on npm
C.02 /

Encoded advisor judgment

Every engagement receives consistent rigor, not partial availability. A multi-agent architecture orchestrates research, writing, analysis and coordination — sustained output of uniform quality regardless of volume.

  • 4–6 week assessment
  • Quarterly executive briefings
  • Continuous advisory under NDA
C.03 /

Coordinated disclosure

When research surfaces a significant finding, we coordinate with the affected vendor and, where applicable, with ANCI / the National CSIRT. Aligned with ISO/IEC 29147 and under the contractual framework enabled by Law 21.459 (Chile).

  • 90-day window
  • Regulator liaison (ANCI · CSIRT.gob.cl)
  • End-to-end coordination

The Coverage Gap Assessment is the entry point to every advisory relationship with Reizan.

Request Coverage Gap Assessment
§ 04 · Observatory

Observatory data.

Figures measured over Chile’s regulated universe, published in an academic record with a permanent DOI and re-measured every 90 days.

1.7%

of critical operators publish a verifiable disclosure channel.

16 of 915 operators · the remaining 98.3% has nowhere to receive the report.

915

operators of vital importance designated by the State.

Exempt Resolution No. 87 · Official Gazette 16-Dec-2025.

84%

have their email authentication misconfigured.

766 operators with deficient SPF/DKIM/DMARC: their email can be spoofed.

View the Observatory

Inaugural measurement 4-Jun-2026 · 90-day cadence · next cut 2-Sep-2026.

§ 05 · Standards

Alignment with international frameworks.

ISO
29147
Vulnerability Disclosure
ISO
30111
Vulnerability Handling
DOJ
2017
VDP Framework
NCSC
NL
CVD Guidelines
MITRE
ATLAS
AI Threat Landscape
NIST
AI RMF
AI Risk Management
OWASP
LLM
AI Application Top 10

Alignment with these frameworks does not imply formal certification. Reizan adopts them as public methodological references, adapted to the applicable Chilean legal framework.

§ 06 · About Reizan

An independent AI-native cyber advisory for regulated LATAM.

Reizan is an independent cybersecurity advisory practice for regulated critical infrastructure across Latin America. We pair continuous, at-scale research with regulator-aware advisory, covering ground that traditional Big Four audits and pentests structurally miss.

Our AI-native architecture orchestrates research, analysis, writing and coordination. It is an execution capability — built to deliver consistent rigor regardless of volume — not a marketing layer over a traditional consultancy. It already operates with an active client.

Reizan operates through AlmaAI SpA, a current Chilean legal entity. Our independence is structural: we do not resell vendor products or broker licenses. The moat is regulatory independence and methodological rigor.

Operating principles

  • P01Structural independence. We do not resell vendor products or broker licenses. Regulatory independence is the moat; advisory is delivered free of conflicts of interest.
  • P02Structural compliance. Everything we build is designed to align with the applicable Chilean regulatory framework, and with ISO/IEC 29147 + 30111 — not as a legal afterthought.
  • P03Research as a product. The Coverage Gap study is published in open access with a permanent DOI (Zenodo · CC-BY-4.0). Supporting tools are released on npm under Apache 2.0.
  • P04Confidentiality of findings. Specific reports, names of affected operators and technical details of unpublished vulnerabilities are handled with professional rigor and under Law 21.459 (Chile’s safe harbor).
§ 08 · Next step

Ready to close your coverage gap?

A 4–6 week diagnostic sprint: executive report, coverage dashboard and prioritized roadmap. Response within 48 business hours.

Request Coverage Gap Assessment